10 ms·
Create a firewall between your personal and professional time. Another name for this is “setting healthy boundaries”. Always create new accounts for anything w
by shaggyfrog 5y ago
Create a firewall between your personal and professional time. Another name for this is “setting healthy boundaries”.
Always create new accounts for anything work related -- GitHub, Apple ID, whatever.
Don’t install work apps on your personal phone. Don’t enrol your personal phone in corporate MDM. If they want you to use a device for work, ask them to give you one.
Don’t do personal stuff on your work devices. Don’t do side project work on your work devices. Only do work for your employer on your work devices. Turn it off when you’re done work and leave it off until you start work the next day.
Be very clear on all your contractual obligations related to this before you start a new job. Ask to see ahead of time all the paperwork they will ask you to sign, so there are no last-minute surprises (“oh, you want to own anything I create outside of working hours?”).
Firewall yourself to protect yourself.
Edit: One more: don’t use corporate WiFi with your personal devices
- harry8 5y agoDo apple let you have multiple accounts? Facebook don't (as I understand it, I have one less). Don't google also say you have to use your real name etc? If they do it's the stroke of a key to make it a ToS violation for employees to have any personal, privacy. Which seems to be their endgame for everyone. Their issue with facebook google etc is that it's not apple doing it as far as I can tell.
- brokenmachine 5y agoPersonally I think it's a great thing if Apple employees have to dogfood their own privacy violations! It might be the only way things start heading in the right direction. Hopefully an exec gets caught up in a CSAM hash collision fiasco.
- hammyhavoc 5y agoThis sounds like advice learned the hard way. Stay well, and don't burn out!
- pbreit 5y agoI doubt it. I've never heard first-hand of anyone running into any trouble that this would mitigate. Some people are just crazy overzealously fearful of employers and BigCos.
- harry8 5y agoYou don't hear about the trouble that people avoid. So...
- Silhouette 5y agoYou also wouldn't hear about the trouble someone didn't avoid if the subsequent legal settlement included a gag clause as well as seizing control of the affected IP and a large financial element. Never accept terms that give your employer control over anything you do independent of work that doesn't affect your performance at work. There is nothing in it for you and the only reason it would be of value to them is if they intend to abuse it.
- falcolas 5y agoRead the parent of the linked tweet. Nudes becoming part of a court record.
- pbreit 5y agoI read it but couldn't really determine what exactly happened or how true it was.
- AlexandrB 5y agoNot first-hand, but this other thread is an example: https://news.ycombinator.com/item?id=28241917 https://news.ycombinator.com/item?id=28241917 And it's not about being fearful. It's about realizing that the relationship between you and your employer is often adversarial. They want to pay you as little as they can get away with for the most work possible. You want the exact opposite. Otherwise why would you have to "negotiate" for a higher salary when you were hired?
- Jarwain 5y agoThis makes sense for most employees of a corporation; is this also relevant for upper management or C suite executives? I'm curious about if these kinds of boundaries are established even in the "upper levels"
- shadilay 5y agoThis is relevant to everyone. Executives are even more likely to be involved in litigation.
- Causality1 5y agoAnd if you can't resist using a work device for something non-work-related, please restrict your use to things you wouldn't mind having printed out and sitting on your boss's desk.
- falcolas 5y agoOr read out loud and passed around in court. See the parent of the linked tweet.
- renerthr 5y agoI checked the parent tweet but still don't understand what you mean. Could you please elaborate?
- pgeorgi 5y ago"legal forced me" and "permanent evidence locker" = these texts are part of a legal discovery process (e.g. somebody sued Apple and their lawyers get a certain kind of access to Apple's corporate data) If there's value for the other side to present the boob pictures as evidence in trial (e.g. in an attempt of character assassination), it will be rather hard to have them not passed around in court now that they're part of the "evidence locker" (as they call it) even though there were 100% personal and unrelated.
- renerthr 5y ago> their lawyers get a certain kind of access to Apple's corporate data Whose lawyers? The plantiff's? Or the defendant (Apple)'s?
- stjohnswarts 5y agomy cutoff is whether I would send the email to my grandmother or not lol. I would never merge a personal and work account. They would just have to hand me my pink slip if they didn't like that.
- MattGaiser 5y agoI'm really surprised at the number of personal GitHub accounts that are being used in my org and at others. I guarantee their access isn't being removed when they depart. And it seems common at a ton of companies.
- kondro 5y agoBecause GitHub makes it hard (i.e. impossible) to manage multiple accounts. No account switching on the website, no easy way to use multiple SSH keys to access multiple accounts when using Git.
- MattGaiser 5y agoShouldn't you mostly be using them on separate computers though? The rare times I need my personal one at work (to view how I solved something before), I just open Incognito.
- SturgeonsLaw 5y agoObligatory plug for Firefox Containers
- kondro 5y agoI'm self-employed and always on-call. Not suggesting this is the right way for anyone else, but trying to unravel a combined life to even multiple accounts on a single computer sounds like a nightmare.
- dasyatidprime 5y agoGitHub forbids multiple free accounts. https://docs.github.com/en/github/site-policy/github-terms-of-service#b-account-terms https://docs.github.com/en/github/site-policy/github-terms-o...
- Waterluvian 5y agoIdeally your employer should pay for seats for their GH Org.
- anonuser123456 5y agoPay for content and services.
- dasyatidprime 5y agoHaving a workplace sponsor a separate GitHub account for your work there would be reasonable, but is this actually common practice? I certainly wish it were, for the above reason, but I can't speak to the reality.
- MattGaiser 5y agoIs it considered free if you are using it with an organization?
- 3np 5y agoNot if the org is paying for your seat.
- MattGaiser 5y agoMy question was more, if I create a free account and it is linked to an organization, is that a paid account? The company didn't make my account, I did.
- 3np 5y agoNote: Speculation. Without actually reading the ToS properly, I imagine you're good if your org is paying for your seat in their org (as opposed to a free org, but if it's a company with private repos I'd assume it's the case). That'd be reasonable. If reality is that you actually meed individual billing for each individual account, that would be kind of crazy and I hope that's not the case.
- Spooky23 5y agoThis. +100 I used to think people were paranoid about this stuff until I ran a big email system. Most big companies have a department in compliance or counsel that reads your mail, either in response to a complaint or randomly depending on the industry. Accused of sexual harassment? Your JDate and Match emails support the idea that you’re lonely. An external entity thinks somebody embezzled money? Your late credit card notice projects that you have money woes.
- tlogan 5y agoExactly. And do not sign up for online services you are using personaly with work email.
- lostlogin 5y agoI work in healthcare. It blows my mind how many people use a work email for communication regarding medical appointments including results and very personal information. I’m a complete outlier in how conservative I am with this stuff and I’m nowhere near as fastidious as the HN gold standard.
- Silhouette 5y agoIt blows my mind how many healthcare providers routinely transfer sensitive information over insecure channels like email in the first place and ask the patients or carers involved to do the same. The most basic data protection regulations enshrined in law in my country are being openly violated, to say nothing of medical ethics and patient confidentiality.
- pbreit 5y agoI don't follow ANY of this advice and am unlikely to do so anytime soon.
- ramraj07 5y agoExactly. I’m not saying trust my employer or that I dont, I don’t care that much. Logging into slack on my phone doesn’t give them access to all my life. I don’t have to be a slave to the company but I don’t have to be a slave to paranoia either.
- gurchik 5y agoPersonally there is a difference between logging into Slack on my phone and logging into email (which requires me to enroll into the MDM). I do the former on my personal cell phone, but I would never do the latter. There are many mistakes the company can make (like wiping my personal phone after resigning from the company) to make me regret that decision. But installing Slack is different, I can shut off the notifications and it is oftentimes convenient for me to have the access there if I need it.
- emodendroket 5y ago> There are many mistakes the company can make (like wiping my personal phone after resigning from the company) to make me regret that decision. How much would you even notice this these days, with everything synced to the cloud?
- Riseed 5y agoI would certainly notice because I go out of my way to ensure everything on my device is not synced to the cloud.
- emodendroket 5y agoI'm going to guess there are not a lot of people who are assiduously avoiding any cloud sync and then adding their work e-mail to their phones.
- throwaway98797 5y agolol you havent worked in sales.
- kova12 5y agowhat's it like in sales?
- throwaway98797 5y agoyou hop between companies in the same industry contacts are fluid. everyone takes their reputation with them. everything is blended. you learn to never put anything questionable in writing. Most people dont even hint at things, just not worth the risk. drinking create plausible deniability of what you said or what was remembered. information spreads deals get closed. and im talking about things that are perfectly clean but may not apear that way if written. sort of like in person you can say “grab me a burrito” but if you write it as a request its hard for it to not come off as demeaning.
- MattGaiser 5y agoThe need for "authenticity" with "this is my personal cell number"?
- rtpg 5y agoEvery salesperson I know has two cell phones.
- throwaway98797 5y agoand some of the good contacts get the personal number.
- Teever 5y agoSounds like some people in sales have three phones.
- 5y ago
- JohnFen 5y agoSpot on on all accounts. It's been my policy for a very long time now. I consider having a hard separation between my personal systems and work systems to be a security measure that protects both myself and my employer.
- emodendroket 5y ago> Edit: One more: don’t use corporate WiFi with your personal devices Can't you use a VPN and the guest network and be essentially OK?
- jptech 5y agoI don't ger this either. With TLS/SSL , how is it different than connecting to any public wifi?
- philipswood 5y agoSome corporate setups need a new root CA added - since TLS/SSL is inspected.
- sumedh 5y agoThe workplace admin can see which domains you visit when you use the work wifi.
- acomjean 5y agoThis. Its not a problem until someone is looking to get rid of you. Then they dump the logs. I've seen people fired for watching DVDs at work. Conversly people watching youtube a lot and nothing happening. Early in the web days an admin assistant came to me because they clicked on something on the web and a bunch of pron windows started popping up. She panicked and turned off her computer and was wondering if it was safe to turn back on or would she be fired. It was safe, and nothing happened to her. Someone at a job complained I was reading the news on the web to my boss, when that was my habit at lunch. That was fun.
- A4ET8a8uTh0 5y agoI think the rule is people usually don't care unless it hits them directly at which point it is already game over. I am not super religious about, but I do have boundaries. It is mostly like you said. It is all great until it isn't and employer is building a case against you.
- silisili 5y agoGreat advice. My company last year demanded we have MDM to access email. So now I don't read emails outside of work hours. I assume there's decent reasons behind such mandates, but net net all it does is alienate many people.
- fenomas 5y agoI agree with most of this, but I'm curious about the specific case of Github. If I join a company, are there any big dangers to just having them add my personal GH account to their organizations or private repos, and then if I leave the company they can remove me again? This seems to be how a lot of developers in my orbit do things. (I mean any dangers at the account/permissions/privacy level - separate from "having two separate accounts might be better for work/life balance" sorts of concerns.)
- hoten 5y agoNo. Having a separate GitHub is just a pain. GitHub provides adequate separation itself (you can add multiple emails and configure notifications accordingly)
- barsonme 5y agoWhat’s difficult about it? Personally, I like knowing that my personal GitHub credentials stay only on my personal devices and my work credentials stay only on my work devices. I never have to worry about the two mixing and any problems that might arise.
- derefr 5y agoPresuming you also contribute to FOSS projects, and that you additionally use the FOSS you work on personally at work, there will come a point at which a bug you find at work will require you to fix the upstream FOSS project on your work laptop. At that point, getting the git-commit attribution correct gets annoying.
- XorNot 5y agoThis isn't too hard - Git supports folder path separated config settings, so usually I just have a "foss" and "work" profile. More annoying can be commit signing, but this is actually something GPG has baked right into it - I issue and sign a new key with my work email address while I'm there, and when I quit revoke the key as superceded (and set the expiry to roughly my contract renewal period/performance eval period). The real problem is corporate IT doesn't understand encryption or signing beyond how their vendors pitch it too them as "secure" so trying to extend any of this to actually support business processes is a losing battle.
- Cd00d 5y agoI get that in the "most secure boundary" sense, I should have a work provided phone for work stuff, BUT... I don't want to carry two phones. I'm part of a team that owns some responsibility for fixing things that break in the night. I find it freeing to be able to reply to a Slack or Outlook email while I'm with my kids at the playground. I see the above advice all the time, but I can't help but think it only relates to an IC with no career ambition, no outside responsibility distractions (kids schedules), that's 100% committed to 9-5 life and has little opportunity for big promotion based on being part of a chain of ownership for things that are customer facing. Personally, I've mostly worked at small companies (my preference), and have ambitions. I have a healthy work/life balance, but also don't want my products to fail and occasionally want the flexibility to help my colleagues while AFK. In the end, the above advice is very popular, but I just see a jaded burnout mercenary in a company with tens or hundreds of thousand employees.
- techrat 5y ago> I don't want to carry two phones. Ah, so you're willing to trade privacy for convenience.
- fuyu 5y agoI'm not sure what tone your comment is intended to give off, but does there exist a person who _isn't_ willing to trade privacy for convenience to some degree? One certainly couldn't be using the internet or participating in society if they weren't willing to give up some privacy.
- janderland 5y agoIn many circumstances, yes I am. :)
- manmal 5y agoPrivacy vs convenience is a spectrum, the question is not _whether_ you trade between those, but rather _how much_.
- aaronbrethorst 5y ago
- userbinator 5y agoYou also should not do work stuff on personal devices. Yes, this does include checking work email on your phone. Ask the company to give you one if your work requires that you do. This may be slightly more controversial, but I would extend this firewall to conversations with coworkers --- don't tell them anything that could be used against you either, i.e. mentions of personal projects or accounts. I keep a clear "no real name" policy for personal things which are publicly visible --- including HN --- which avoids the delicate situation of people I know who have had their employer complain about stuff with their name on it, in their personal life, that someone else had found and didn't like.
- dheera 5y ago> Don’t install work apps on your personal phone. 100%. If a company wants me to install an app they'd better provide the phone. > Edit: One more: don’t use corporate WiFi with your personal devices Yep, thankfully we don't need to do that anymore with 4G/5G
- sircastor 5y agoI was sort of into the idea of having my calendar on my phone until I learned my company could remotely wipe my phone at any time. That’s a world of trouble from a misunderstanding, or a bitter IT person.
- risfriend 5y agoAbsolutely agree with separating phones, recently my company mandated MDM policy on phones, and it really messed my phone, there are apps which are separated with work profile but there are very few such apps, what about other apps? Learnt the importance of creating a hard boundary the hard way.
- cameldrv 5y ago+1 on the MDM stuff. I recently had a guy I know lose all his photos after he left a company. The company said that they could only wipe the company partition on his Android phone, but somehow they could wipe the whole thing and pressed the wrong button. Leaving a job is hard enough without having to disentangle a bunch of devices and accounts. If an employer wants the security of MDM, just have them provide you the device. Otherwise, it's your device, and you can be responsible for deleting the company related content on it when you separate.
- kartoshechka 5y agoaaand nothing of this is relevant when WFH
- DoubleGlazing 5y agoI've had issues in the past with employers wanting me to add work email and work apps to my own phone. I always refused. My attitude was, like you said, if you want me to carry around a device connected to my work, then you need to pay for it. But my main reason why though was knowing that managers preferred staff to put work email etc on personal phones, not due to the cost of buying devices for employees, but because it blurred the lines between personal and work domains. You can switch a work phone off at 6:00pm and turn it on again at 9:00am. With a personal phone you have to set up do not disturb profiles and stuff like that to achieve the same separation because you aren't likely to turn it off in the evenings. Admittedly, it's not the hardest thing in the world to setup - but still a bit more effort that just being able to hit the power button. I still had to deal with the extreme annoyance of having my personal number passed around the company without my permission.